I Need IT Support Now
Managed Service Provider Houston Cybersecurity
Shane

Texas Digestive Specialists Hit by Major InterLock Ransomware Attack

Texas Gastroenterology Practice Suffers Major InterLock Ransomware Attack – Patient Information Potentially Compromised

Cybersecurity Alert
InterLock Ransomware Hit Texas Digestive Specialists and Exposed 41,521 Patients. Every Houston Practice Should Read the Postmortem.

A South Texas gastroenterology group lost 263 GB of patient data to the InterLock ransomware group. The playbook that broke it is the same one aimed at Houston healthcare and SMBs right now.

TL;DR
InterLock ransomware breached Gastroenterology Consultants of South Texas (Texas Digestive Specialists) in late May 2025, stealing 263 GB of records. The practice reported 41,521 affected Texans to the state AG; the federal HHS OCR portal lists 44,579. InterLock uses fake CAPTCHA "ClickFix" lures and double extortion, and CISA flags it as an active threat to healthcare.

InterLock ransomware (Texas Digestive) is now a documented case, not a hypothetical. The group breached Gastroenterology Consultants of South Texas, which does business as Texas Digestive Specialists, and walked out with 263 GB of patient data before anyone noticed.

The practice runs clinics in McAllen, Brownsville, and Harlingen and serves the Rio Grande Valley. Attackers got into the network in late May 2025. The practice reported 41,521 affected Texans to the Texas Attorney General on July 24, 2025; the federal HHS Office for Civil Rights breach portal lists a higher total of 44,579 individuals. CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, and we read these breach reports so a Houston owner does not have to. This one is worth the read because nothing about the attack was exotic.

Why this reaches Houston: the same InterLock group is on a CISA advisory as an active threat to healthcare and critical infrastructure across North America. A gastroenterology group in the Valley and a 40-person clinic or CPA firm in Katy sit behind the same class of defenses. The Valley practice just went first.

What Happened to Texas Digestive Specialists?

A late-May 2025 network intrusion, two months of silence, then notification.

InterLock gained access to the Texas Digestive Specialists network in late May 2025, exfiltrated roughly 263 GB of data across more than 215,000 files, then listed the practice on its dark-web leak site. Patient notifications did not go out until late July 2025.

The stolen files spanned care delivered from August 2023 to early 2025. According to the breach disclosure and reporting by the HIPAA Journal, the data included names, Social Security numbers, dates of birth, addresses, medical records, health insurance details, and lab reports with testing dates and clinical findings. One compressed archive alone held more than 20,000 lab reports.

The notification letters do not use the word ransomware. InterLock filled that gap itself by claiming the attack publicly and posting the practice to its leak site. That is double extortion in one move: encrypt to disrupt, and threaten to publish to force payment. Gastroenterology records make the second lever nastier than most, because the details are the kind a patient would pay to keep private.

  • Volume: about 263 GB, more than 215,000 files, in over 16,900 folders per the leak-site claim.
  • Reach: 41,521 Texans reported to the state AG; 44,579 individuals on the HHS OCR portal.
  • Delay: access in late May, disclosure to the Texas AG on July 24, roughly a two-month window before patients could act.
THE TEXAS DIGESTIVE BREACH, BY THE NUMBERS 41,521 Texans reported to the state AG 44,579 individuals on the HHS OCR portal 263 GB data stolen before detection ~2 mo from intrusion to patient notice CinchOps · cinchops.com · Sources: Texas AG breach notice, HHS OCR portal, HIPAA Journal
The Texas Digestive Specialists breach at a glance. The two person-counts differ because the state and federal filings were made separately.

Who Is the InterLock Ransomware Group?

A financially motivated group that CISA and the FBI treat as a healthcare threat.

InterLock is a ransomware group first observed in late September 2024, targeting businesses and critical infrastructure across North America and Europe. On July 22, 2025, the FBI, CISA, HHS, and MS-ISAC issued joint advisory AA25-203A naming its tactics.

InterLock does not pick targets by ideology. The FBI describes it as opportunistic and financially motivated, which means any under-defended network is a candidate. What makes it dangerous to healthcare is the entry method. The group has used drive-by downloads from compromised legitimate websites and the ClickFix technique, where a fake CAPTCHA or error page tricks a user into pasting a malicious command into their own machine. The user does the infecting.

After it lands, InterLock runs a familiar sequence: credential theft, lateral movement, data exfiltration to cloud storage, then encryption tuned for both Windows and Linux virtual machines. The most publicized InterLock case is the April 2025 DaVita breach, which affected more than 200,000 patients of the dialysis provider. Texas Digestive Specialists is smaller, but the method is identical.

  • Initial access: drive-by downloads and ClickFix fake-CAPTCHA lures, not a zero-day.
  • Model: double extortion, with a leak site for victims who refuse to pay.
  • Federal status: named in CISA advisory AA25-203A as an active threat to healthcare and critical infrastructure.

ClickFix Is a Training Problem Before It Is a Tooling Problem

InterLock's favorite way in is a person pasting a command they were told would "fix" a page. CinchOps pairs email filtering and endpoint detection with the awareness training that stops that paste, as part of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

What Should a Houston Healthcare or SMB Take From This?

The Valley practice is a preview, not an outlier.

The lesson is not "gastroenterology is a target." It is that a mid-sized practice with normal defenses lost 263 GB and did not know for weeks. A Houston clinic, dental group, or specialty practice of the same size runs on the same footing.

Houston's medical concentration cuts both ways. The Texas Medical Center anchors one of the densest healthcare economies in the country, and that density is a large surface of small and mid-sized practices, billing companies, and specialty groups feeding into it. InterLock reaches a bigger target by breaking a smaller vendor first, so a 30-person Houston practice that thinks it is too small to notice is exactly the size that gets used as a door.

The delay is the part every owner should sit with. Two months passed between the intrusion and patient notice. In 35 years doing this, the single strongest predictor of how bad a breach gets is not whether someone got in, it is how long they stayed before anyone saw them. That window is detection and response, and it is buyable at SMB scale. Three moves close most of the gap the Valley practice fell into.

  • Cut the ClickFix path: teach staff that no legitimate site asks you to paste a command to "verify" or "fix" it, and filter the sites that host the lure.
  • Watch for dwell: endpoint detection and response flags the credential theft and lateral movement that happen in the weeks before encryption, which is where the Valley practice lost its window.
  • Protect the backups: offline, tested backups turn a ransom demand into a restore job and take away the encryption half of double extortion.
Read the timeline, not the ransom note. This group did not need a genius exploit. It needed one person to paste a command and a network with nobody watching for two months. A Houston practice with 40 people can fix both of those without an enterprise budget. It just needs someone whose job is to watch.
Shane Stevens, CEO, CinchOps - LinkedIn
100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

How CinchOps Helps Houston Practices Avoid the Same Postmortem

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, focused on the detection, response, and backup capability the Texas Digestive Specialists timeline showed was missing.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. InterLock did not win on a novel exploit. It won on a pasted command and weeks of unwatched dwell time, and both of those are things a managed partner exists to close:

  • Anti-phishing and ClickFix defense. Email filtering plus staff training aimed at the exact fake-CAPTCHA and "paste this to fix it" lures InterLock relies on.
  • Endpoint detection and response. Monitoring for credential theft and lateral movement so the dwell window is hours, not the two months the Valley practice lost.
  • Backup and recovery. Offline, tested backups so encryption becomes a restore, not a ransom decision.
  • Network segmentation. Limits on lateral movement so one compromised machine does not hand over the whole patient database.

If you run a law firm, CPA practice, or medical office in Houston or Katy, the Texas Digestive Specialists breach is a scenario you can rehearse against instead of relive. If you could not say today how long an intruder could sit on your network before someone noticed, talk to CinchOps and we will tell you straight.

Frequently Asked Questions

Who was hit in the Texas Digestive Specialists ransomware attack?

Gastroenterology Consultants of South Texas, which does business as Texas Digestive Specialists, was breached by the InterLock ransomware group in late May 2025. The practice runs clinics in McAllen, Brownsville, and Harlingen and serves the Rio Grande Valley. InterLock claimed the attack and posted the practice to its dark-web leak site.

How many patients were affected by the Texas Digestive breach?

The practice reported 41,521 affected Texans to the Texas Attorney General on July 24, 2025. The federal HHS Office for Civil Rights breach portal lists a higher total of 44,579 individuals. The two figures differ because the state and federal breach filings were submitted separately, per HIPAA Journal reporting.

What is the InterLock ransomware group?

InterLock is a financially motivated ransomware group first observed in late September 2024, targeting businesses and critical infrastructure in North America and Europe. On July 22, 2025, the FBI, CISA, HHS, and MS-ISAC issued joint advisory AA25-203A naming its tactics. It uses double extortion and specifically targets healthcare.

How does InterLock break into a network?

InterLock has used drive-by downloads from compromised legitimate websites and the ClickFix technique, where a fake CAPTCHA or error page tricks a user into pasting a malicious command into their own machine. It then steals credentials, moves laterally, exfiltrates data to cloud storage, and encrypts Windows and Linux virtual machines.

How can a Houston healthcare practice avoid a similar breach?

Focus on the three gaps this attack exposed: block the ClickFix paste with training and filtering, run endpoint detection and response to shrink attacker dwell time, and keep offline tested backups. A managed IT provider can deliver all three at SMB scale, which is how a small Houston practice reaches enterprise-grade response without an enterprise budget.

Discover More

Sources

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506